web-clickjacking

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent and does not show malware-like installers or credential theft, but it is explicitly an offensive exploitation technique for AI agents. Risk is driven by enabling clickjacking attacks, not by supply-chain or data-exfiltration behavior.

Confidence: 92%Severity: 76%
Audit Metadata
Analyzed At
Sep 20, 2026, 11:03 PM
Package URL
pkg:socket/skills-sh/noorqureshi%2Fsploitagent%2Fweb-clickjacking%2F@134c435933101d9c14e8e271bfaf93ffeaa79404081259b04e18e917e2ae8a65
Security Audit — socket — web-clickjacking